Back to skill

Security audit

Multi Search Engine

Security checks across malware telemetry and agentic risk

Overview

This search skill is mostly purpose-aligned, but its privacy notice falsely says there is no external data transmission while it sends search queries to multiple third-party engines.

Install only if you are comfortable with your search terms being sent to external search providers, potentially several per query and across regions. Do not use it for secrets, confidential project names, regulated data, or sensitive personal searches unless you first constrain which engine is used.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The documentation states that no personal data is collected or transmitted and that all operations run locally, but the skill necessarily sends user search queries to external search engines. Search terms can contain sensitive personal, business, or investigative data, so this is a materially misleading privacy claim that can cause users to disclose information they otherwise would not share.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The skill automatically routes queries to Chinese or international engines based on detected language without user consent or an override. This can expose sensitive queries to jurisdictions or providers the user did not intend, increasing privacy and compliance risk, especially for internal, regulated, or politically sensitive searches.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The main description and workflow present the feature as search integration and web crawling but do not clearly warn that queries may be sent to multiple third-party search engines. Without a prominent disclosure, users may unknowingly transmit confidential prompts, internal project names, or personal data to several external providers.

Missing User Warnings

High
Confidence
99% confidence
Finding
The Security & Privacy Notice is actively misleading because it says no personal data is transmitted and all operations run locally, while the skill's core behavior is remote querying of external services. Misrepresenting network exfiltration and privacy properties is dangerous because it undermines informed consent and may lead to unauthorized disclosure of sensitive user input to multiple third parties.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The documentation explicitly shows a parameter to disable safe-search filtering (`kp=-1`) without any warning, age gating, or policy guidance. In a reusable agent skill, this can normalize retrieval of explicit, unsafe, or otherwise inappropriate content and increases the chance that downstream users invoke unsafe searches unintentionally.

Missing User Warnings

Medium
Confidence
76% confidence
Finding
The cached-page example is framed as a way to view deleted content, which can encourage bypassing content removal intent, privacy expectations, or site-owner decisions. Even though it uses a public cache, presenting it without ethical or privacy guidance makes misuse easier in contexts involving sensitive or removed material.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.